Back to pricing

Desialth · Foundlete

Privacy Notice

Last updated 19 August 2026

1. Who we are

Desialth operates the Foundlete app and website. Desialth is the data controller for the personal data described in this notice: we decide why and how it is processed. You can reach us through the support channel in the app.

2. What we collect and why

  • Account data (name, email, login credentials, sign-in provider such as Google) — to create and secure your account and to sign you in. Legal basis: performance of our contract with you.
  • Profile and founder details (display name, startup name, stage) — to personalise your dashboard and squad presence. Legal basis: contract.
  • Wellness inputs (morning check-ins, protocol completions, streaks, meetup RSVPs) — to calculate readiness and run the features you use. Legal basis: contract.
  • Morning note photos and their transcriptions (images, extracted goals, gratitude, mood, summaries) — to store your journal and generate observations. These are private to your account. Legal basis: contract; where the notes reveal sensitive details, your explicit consent given by choosing to upload them.
  • Support messages — to answer your questions. Legal basis: legitimate interest in supporting our users.
  • Usage, device data and IP address — for security, fraud prevention, debugging and improving the product. Legal basis: legitimate interests, and legal obligation where applicable.

Payment card details are collected and processed by Paddle, not by Desialth; we never see your full card data.

3. Who we share data with

  • Service providers and subprocessors — cloud hosting and database storage, and the AI provider that transcribes and summarises your morning note images. They act on our instructions only.
  • Paddle.com, our Merchant of Record, for the sale of Foundlete Pro, subscription management, payments, invoicing and tax compliance.
  • Professional advisers — legal and accounting, where needed.
  • Authorities — where required by law or to protect our legal rights.

We do not sell your personal data.

4. International transfers

Our providers may process data outside the UK/EEA. Where that happens we rely on appropriate safeguards, such as adequacy decisions or Standard Contractual Clauses.

5. Retention

We keep your account, journal and wellness data for as long as your account is active. You can delete individual morning notes (including the stored photo) at any time from the Notes tab. When you close your account, we delete or anonymise your data within a reasonable period, except where we must retain records for legal, tax or accounting purposes.

6. Your rights

Subject to applicable law, you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time. Contact us in the app and we will respond within one month. If you are in the UK or EEA, you may also complain to your local data protection supervisory authority.

7. Security

We apply appropriate technical and organisational measures: encrypted transport, access-controlled storage, and row-level database rules so that only you can read your own notes, photos and check-ins.

8. Cookies and local storage

We use strictly necessary cookies and browser local storage to keep you signed in and to remember your app preferences (such as your onboarding progress and offline app state). Paddle sets cookies needed to run checkout securely. We do not use advertising cookies. You can clear or block cookies in your browser settings, though parts of the app may then stop working.

9. Changes

We will update this notice as the product changes and revise the date above. Material changes will be highlighted in the app.